Maianmedia's vulnerability footprint concentrates in its affiliate marketing platform product, with the durable signal centered on web application input-handling and file-upload risks including cross-site scripting, code injection, and unrestricted file uploads. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maianmedia over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39402HIGH MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated | Sep 20, 2021 | 7.2 | 24 | NO | NO |
CVE-2021-41420MEDIUM A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated user | Jun 16, 2022 | 5.4 | 19 | NO | NO |
CVE-2021-41421MEDIUM A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel. | Jun 16, 2022 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maianmedia.
Media articles that mention a CVE ID that affects a product developed by Maianmedia — matched by CVE ID, not by vendor name.